← Back to Tech & Science

Wiz Research Finds Widespread Default Key Vulnerability in LiteLLM Gateways

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — Security researchers at Wiz Research have identified a critical configuration flaw affecting nearly one in ten internet-facing LiteLLM gateways globally, exposing sensitive provider API keys and cloud identity credentials to unauthorized access. The vulnerability stems from the use of default example credentials left active during server setup, allowing attackers to bypass authentication mechanisms on exposed systems.

The discovery was announced on Sept. 10, 2026. Wiz Research reported that a significant portion of LiteLLM instances deployed across public networks accepted the hardcoded example admin key 'sk-1234'. In some cases, gateways were found with no administrative key configured at all, leaving them entirely open to exploitation. When compromised, these gateways grant attackers direct access to the underlying large language model providers and cloud infrastructure accounts linked to the service.

LiteLLM is a popular open-source library designed to standardize API calls across various artificial intelligence models. Its documentation includes setup guides that utilize placeholder credentials for demonstration purposes. Wiz Research found that many administrators failed to replace these default keys with secure, unique values before deploying their gateways to the public internet. This oversight effectively handed control of high-value assets to anyone scanning for vulnerable endpoints.

The exposure of API keys and cloud IAM credentials poses severe risks, including unauthorized consumption of paid AI services, data exfiltration, and potential lateral movement into broader corporate networks. Attackers could leverage stolen keys to generate content at the victim's expense or access sensitive data stored within connected cloud environments.

Wiz Research emphasized that the issue is not a software bug but a misconfiguration resulting from default settings remaining in production environments. The security firm noted that the prevalence of the vulnerability suggests a widespread gap in deployment practices among organizations utilizing LiteLLM for AI orchestration.

LiteLLM developers have not yet issued a formal public statement regarding the specific findings or outlining immediate remediation steps beyond standard configuration advice. It remains unclear how many organizations have been actively targeted since the vulnerability was first identified or if any data breaches have already occurred as a result of the exposure.

Security experts advise administrators to immediately audit their LiteLLM deployments, rotate all default keys, and ensure that strong, unique authentication credentials are enforced across all internet-facing instances. The incident highlights the ongoing risks associated with insecure default configurations in rapidly adopted open-source tools.

Discussion

0 / 2000